Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Capture It - Easy Screenshot Tool (Full Page, Selected, Visible Area)

lkalpedlpidbenfnnldoboegepndcddk
Risk Score
5.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 6,000
Rating 4.5
Last updated 2026-08-23
Manifest version MV3
CSP present ❌ no
Developer paintersky85@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + 3rd-party sharing without scoping to this extension — scores maximum privacy risk.
  • Uninstall and install URL hijacks both active — classic monetization/tracking shell behavior.
  • No CSP + multiple innerHTML sinks + function_constructor in bundled UI lib — XSS attack surface on every visited page.
  • Gmail dev email, no verified publisher, privacy policy on personal domain not scoped to extension.
  • Description promises recording but lacks tabCapture/desktopCapture — permission/promise mismatch suggests deceptive listing.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and setUninstallURL hooks present; monetization/tracking shell pattern per rubric (+3.0 Webstore each).
  • privacy_policy_scope_extension=false + data_collection=true + third_party_sharing=true crx Policy fetched but admits collection+3rd-party sharing without scoping to extension — v3.5(D) → +10.0 Privacy.
  • free_webmail_dev + no_verified_publisher store paintersky85@gmail.com; no verified publisher, no featured badge. Reputation starts 5.0 +1.5 webmail = 6.5.
  • dom_sink_innerhtml_userctrl (x3) + function_constructor + csp_present=false crx Three innerHTML sinks + new Function(); no CSP — DOM-XSS risk elevated per FIX B rule.
  • description_promise_mismatch store Listing promises recording capability but manifest lacks tabCapture/desktopCapture (+2.0 Webstore).
  • js_external_hosts: www.cs.rit.edu crx Extension contacts university domain (cs.rit.edu) — unexpected for screenshot tool; supply-chain risk.
  • monetization_hits: google-analytics.com crx Analytics telemetry present; category=Screenshot not in exempt list (+1.0 Webstore telemetry-tier).
  • host_permissions=<all_urls> + content_scripts on all http/https manifest Content scripts injected on every site with broad host access — high reach for screenshot function.

Permissions Breakdown

  • storage low Local data persistence; expected for screenshot settings.
  • declarativeNetRequest medium Can block/redirect network requests; scope unclear for screenshot tool.
  • unlimitedStorage low Allows large local storage; plausible for full-page screenshots.
  • offscreen low Off-screen document rendering; used legitimately for capture.
  • system.display low Reads display info; plausible for screenshot dimension logic.
  • <all_urls> (host) high Content scripts injected on every site; broad reach for a screenshot tool.

Pillar Scores

Permissions4.50
Reputation6.50
Network3.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA 513d1074efc6…
Force block — not fired
Score recovered no
Elapsed